|
|||||||||
|
|||||||||
|
|||
|
from geo's blog
In the KBAG section of the img3 files, you'll find 0x20 bytes after the section header. Decrypt them with the hardware AES engine and get IV: 29681F625D1F61271EC3116601B8BCDE KEY: 850AFC271132D15AE6989565567E65BF (this is the 2.0 ramdisk) Does this mean that there can be a ramdisk expolit for 2.0, which means custom payloads on boot? as chronic mentions this is a major disovery. |
|
|||
|
just to follow up, i beleive the major reason that pwnage does not work is because the ramdisk eploit was closed in beta 4 of fw2.0.
Does this mean that with this knowledge pwnage can again work? Also its is the ramdisk exploit that shut down Zibri and his antics. Manybe he will resurrect with this knowledge. |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
|
|